It seems that #Josephbeeton found a #RCE in Togglz exposed on localhost via in-browser executed JS. Now, I’m not even close to an expert, but some of this looks a bit like @taviso’s #dnsrebinding attack type? #hacklu2025